tux7350

joined 1 year ago
[–] tux7350@lemmy.world 9 points 6 days ago

"I award you no points, and may God have mercy on your soul"

https://youtu.be/yptXkLglKkA

[–] tux7350@lemmy.world 2 points 1 week ago* (last edited 1 week ago)

I'm going to suggest something a bit more out there. You can setup this whole thing with NixOS. I have a bunch of docker containers that run as a systemd service, declared with Nix and personally, I like it very much. It's also got everything else you want but the atomic upgrades are top tier in NixOS.

For example if you want NoIP and Cockpit just add this bit to your configuration.nix

    environment.SystemPackages =[
        pkgs.noip
        pkgs.cockpit
    ];

Adding something like docker or podman is just as easy with a one line like

    virtualisation.docker.enable = true;

There is always a bit of a learning curve when doing anything with Nix but I find the buy in to be worth it. Here's a blog post about converting docker compose files over to the Nix format. This really isnt necessary as you could just make the systemd service run a oneshot against a docker compose file but this blog has a lot of nice examples.

https://mrupnikm.github.io/en/posts/nix-docker-containers/

If you have any questions please let me know :D

[–] tux7350@lemmy.world 2 points 1 week ago* (last edited 1 week ago)

No, you're right! They have the best name, DERP relays lol. When tailscale can't find a node over UDP , it switches over to TCP and runs the encrypted traffic through the DERP relays.

[–] tux7350@lemmy.world 3 points 1 week ago (1 children)

It shouldn't mess with your current routing but if you're running other VPNs you may run into issues.

After you join the machines to the tailnet, each machine gets a new IP address ( only visible to other machines in the tailnet), by default it's a 100.x.y.z you can check the tailnet for the device IP.

Now you can keep the port closed on your router and it will still be accessible over the usual lan ip and port. But when you want to access remotely, turn on tailscale and connect using the tailnet IP.

Another cool thing you can do with this setup is turn your home server into an exit node. By default it will only route things that are in the tailnet (100.x.y.z subnet). But if you turn your home server into an exit node you can funnel all your traffic back through the exit node. Instant free VPN back home!

[–] tux7350@lemmy.world 2 points 1 week ago (3 children)
[–] tux7350@lemmy.world 5 points 1 week ago (5 children)

Unencrypted HTTP can mean that anyone can see your traffic as it passes through their network. Your ISP will see that traffic. If you're streaming pirated music and you're in a country that cares about those things, might not go very well. From a security stand point though, you still wouldn't want to trust the authentication on the open port. A vulnerability may exist that you don't know about. It's always better to keep them closed and add another layer or two between your home computer and the public.

Tailscale let's you tunnel into your home network without opening any ports, and it encrypts the traffic. Much safer way of doing it.

[–] tux7350@lemmy.world 1 points 2 weeks ago

What kinda issues are you having? Most of my problems with Nix are solved with overlays or creating a module. Admittedly, in order to do that you still have to know how to fix your issue the usual linux way. Afterall, Nix is more of an abstraction tool IMO; good for replicating something across a ton if devices. If you don't need that, there's other distros that work much better out of the box.

[–] tux7350@lemmy.world 7 points 2 weeks ago (12 children)

Another tip, please be very careful when exposing ports to the public. With docker you're already mitigating your attack surfaces but an open port allows anyone to make a connection and there are lots of bots out there looking for open ports and vulnerabilities. A good alternative would be to setup wireguard and instead then connect through that or if you like simplicity check out Tailscale.

[–] tux7350@lemmy.world 10 points 2 weeks ago

It took me a bit to find this video for anyone looking for it. The more I see interactions with Tim, really shows how wholesome of a person he is.

https://youtu.be/lMcbJlidTCA

[–] tux7350@lemmy.world 4 points 2 weeks ago (1 children)

This is kinda how I've come to look at it. You cannot ask questions of fact to a machine that works in probabilities.

[–] tux7350@lemmy.world 4 points 3 weeks ago (1 children)

Ha, ya know? I think I know some people who will just regurgitate whatever input they receive

........

:(

view more: next ›